Contivity 2700 to Nokia Checkpoint
"Little, Mike (BHS)" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
All, I have a Contivity 2700 (v4.80.124) connecting to a vendor's Nokia IP 330 running Check Point 4.1. We can establish a site-to-site tunnel. He can pretty much get into our network with no problems from his side (ping, PCAny, etc.) but I'm not seeing round trip traffic initiated from my side to his using any protocol. I see packets leaving my CES2700 and he says he sees them coming in "unencrypted"? I don't know what's happening on his end afterwards or where to go with this one. Subnets (encryption domains) appear to be OK and I have the firewall wide open on my side at this point. We also have various other vendors connecting fine (none running Check Point). Here is some additional info: - ESP - Triple DES with MD5 Integrity: Enabled IKE Encryption and Diffie-Hellman Group: Triple DES with Group 2 (1024-bit prime) Vendor ID: Enabled Aggressive Mode ISAKMP Initial Contact Payload: Enabled Perfect Forward Secrecy: Disabled Compression: Disabled Rekey Timeout: 08:00:00 Rekey Data Count: (None) ISAKMP Retransmission Interval: 1440 ISAKMP Retransmission Max Attempts: 4 Keepalive interval: 00:01:00 Keepalive (On-Demand connections): DISABLED Anti Replay: DISABLED As usual, any information that might help is appreciated. Thanks, Mike Little Network Services Baptist Healthcare System _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn